---
id: CVE-2026-105139
title: >-
  Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that
  allows authenticated users matching any vMCP profile to reach prompts and
  resources of ungranted components
summary: >-
  Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that
  allows authenticated users matching any vMCP profile to reach prompts and
  resources of ungranted components. Because profiles were enforced only on
  tools, atta…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: obot-platform
product: obot
affected:
  - obot >= 0.26.0 < 0.26.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:17:19.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105139'
references:
  - url: 'https://github.com/obot-platform/obot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L231
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/blob/8cfac5d38baa4fa0719e7975b7542608ff8bc932/pkg/mcp/vmcp.go#L97
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/commit/8d92701c2018a7b9dd6d692498fa5f41fdb912ea
    label: disclosure@vulncheck.com
  - url: 'https://github.com/obot-platform/obot/releases/tag/v0.26.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/obot-platform/obot/security/advisories/GHSA-xhpw-65qw-wj6m
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/obot-0.26.0-before-0.26.2-authorization-bypass-via-vmcp-profile-prompts-and-resources
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T13:31:04.596Z'
---

## Overview

Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts and resources of ungranted components. Because profiles were enforced only on tools, attackers can access prompts, resources, and resource templates through the vMCP owner's shared component connection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
